Impact
Improper neutralization of input during web page generation in Haider Ali's Bulk Categories Assign plugin (versions up to and including 1.0) provides a reflected cross‑site scripting (XSS) vulnerability. When a user accesses URLs containing malicious query parameters, the plugin outputs them without proper escaping, allowing an attacker to execute arbitrary JavaScript in the victim's browser, potentially leading to session hijacking, defacement, or phishing attacks on visitors who view malicious links.
Affected Systems
WordPress sites that have installed the Bulk Categories Assign plugin by Haider Ali, version 1.0 or earlier, are affected. The vulnerability impacts all installations that have not upgraded beyond the listed version.
Risk and Exploitability
This vulnerability scores a CVSS base of 7.1, indicating a medium‑to‑high level of severity. The EPSS score is listed as less than 1%, suggesting a low probability of exploitation at this time, and it is not currently cataloged in CISA's KEV. The most likely attack vector involves a remote attacker crafting a malicious URL that includes unsanitized input, which a naive user might click, resulting in reflected XSS. Since the flaw is purely client‑side, no additional privileges are required, but the impact can be significant if the user is an administrator or otherwise has elevated privileges.
OpenCVE Enrichment
EUVD